CVE-2025-1638

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 1, 2025
CWE ID 288

Summary

CVE-2025-1638 is a critical vulnerability affecting the Alloggio Membership plugin for WordPress. The issue lies in the plugin's failure to validate user identities during the Facebook and Google login processes, specifically within the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions. This flaw allows unauthenticated attackers to bypass authentication and log in as any user, including administrators, without requiring a password. This vulnerability poses a significant risk for WordPress sites using the Alloggio Membership plugin and is advised to be addressed immediately by updating to the latest version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Alloggio Membership Plugin

Affected Vendors

  • WordPress